Draft for legal review. Version 1.3 · Effective June 4, 2026 — the version currently under counsel review. Items marked “verification pending” are asserted by design and are being independently tested before they are claimed as verified.

Swomi Inc. — Confidential — Draft for Legal Review

Swomi Privacy Policy

Comprehensive Privacy Policy — Actor Model, Two Levels, and the Reasoning/Intelligence Firewall

Version: 1.3 (Draft for Legal Review) — supersedes v1.2

Effective Date: June 4, 2026 | Entity: Swomi Inc., incorporated in Canada

Contact: privacy@swomi.com | DPO: dpo@swomi.com

v1.3 aligns this policy to the canonical Swomi Model Specification v1.0. It adds the Actor model, sovereign profiles, the reasoning/intelligence firewall, group/shared-intelligence participation with a contribution retraction window, the crisis-support path, and an explicit statement of what Swomi does not do (no scraping, no sourcing of non-users). Items marked “verification pending” are asserted by design and are being independently tested.

1. Introduction

When you use Swomi, you are trusting us with your information. We treat that as a responsibility and we work to keep you in control. This Privacy Policy explains what information we collect, why, and how you can access, manage, export, and delete it.

Swomi is an AI platform built around Actors — avatars, virtual actors, and autonomous agents. Some Actors are operated by or learn for a specific person; others are fully system-created. This distinction matters legally, and we explain it in Section 4. Throughout, “you” means the natural person behind a user-bonded Actor.

Swomi Inc. (“Swomi,” “we,” “us,” or “our”) is incorporated in Canada. We comply with PIPEDA, Quebec’s Law 25, the EU GDPR, the UK GDPR, Canada’s Anti-Spam Legislation (CASL), and the California Consumer Privacy Act (CCPA/CPRA) where applicable. If EU or UK law applies to you, see Section 12.

2. What Information We Collect

2.1 Security Data (Zone A) — shown via the Security Banner

Before you log in, and even if you remain anonymous, our systems automatically analyze your connection to protect against bots, attackers, and abuse.

2.2 Your Sovereign Profile (Zone B) — requires explicit opt-in

Important: before you opt in, we do not build any behavioral or personalization profile of you. No communication-style, preference, topic, or psychological inference is computed or stored. The only processing before opt-in is the Zone A security processing above.

If you opt in when creating an Actor (or later in Privacy Controls), that Actor begins to build a sovereign profile to tailor how it works for you. “Sovereign” means you govern it: you can inspect, export, and revoke it at any time. It is bound to that specific Actor — if you operate several Actors, each has its own profile and its own consent.

Nature of data: this data is pseudonymized, not anonymous. The pseudonymized identifier can be re-linked to you (for example, to bring your profile to your account on consent), so it is personal data under GDPR and Law 25, and we treat it accordingly. The fact that an Actor is an avatar does not make it anonymous — an avatar is a pseudonym.

2.3 Sensitive Inferences (Special Category Data)

Our AI may detect that a conversation touches on psychological or emotional attributes (for example, resilience or one’s relationship with mortality).

2.4 Information You Provide (Lens 2)

2.5 What We Do Not Do Before You Opt In

To be unambiguous: personalization is off by default. Until you grant Zone B consent, Swomi does not create a behavioral profile, does not score communication style or personality, does not infer topics or preferences, and does not generate or store psychological inferences. The product is fully usable in this default state.

2.6 What We Never Do

Some commitments do not depend on your settings:

3. How We Use Your Information (Lawful Bases)

Purpose Lawful Basis Description
Service delivery (including your Actor performing its assigned tasks) Contract (Art. 6(1)(b)) Run your account; your bonded Actor does the job you asked of it. This covers doing the task — not building a durable profile, which requires consent.
Security (Zone A) Legitimate Interest (Art. 6(1)(f)) Detect bots, prevent attacks, protect system integrity. Firewalled from personalization.
Agent-to-agent operation (world / plumbing) Legitimate Interest (Art. 6(1)(f)) Allow Actors to interact so the service functions; the world/interaction graph is anonymized and is not used to profile members.
Personalization (sovereign profile, Zone B) Explicit Consent (Art. 6(1)(a)) Build and use a profile — only after opt-in — so your Actor tailors how it works for you.
Group participation & contribution Explicit Consent (Art. 6(1)(a)) Join groups you select; optionally contribute your Actor’s learning to a group’s shared intelligence (see §5.2).
Sensitive inferences Explicit Consent (Art. 9(2)(a)) Retain special-category inferences only after just-in-time consent.
Model improvement Explicit Consent (Art. 6(1)(a)) Improve Swomi’s own systems on pseudonymized/aggregated data — opt-in only, and separate from group contribution.
Legal compliance Legal Obligation (Art. 6(1)(c)) Comply with Canadian, EU, UK, and US law.

We do not use your data for targeted advertising, and we do not sell your personal data.

4. How Swomi Is Built: Actors, the Two Levels, and the Firewall

4.1 Actors

Swomi processes data through Actors. There are two kinds, and the difference determines how the law applies:

4.2 The Two Levels and the Firewall

Swomi separates reasoning from intelligence:

A firewall sits between them. Your intelligence-level data (your profile, identifiers, device fingerprint, group memberships) is never sent to the reasoning engine; identifiers and linkage are stripped from what is sent; and the reasoning engine is contractually bound not to retain or train on it. This is what keeps the reasoning provider a processor rather than a recipient of your personal data. (Verification of the stripping is ongoing.)

4.3 Zones and Lens 2

4.4 Your Sovereign Profile Stays With You

Your profile is never shared as a profile — sharing a profile would disclose you. What can be shared, with your separate consent, is intelligence: learned capability, abstracted from you, contributed to a group (see §5.2). Consistent with §2.5, no Zone B profile exists for you unless and until you opt in.

5. Consent Management

5.1 The Consent Sequence

We ask for consent in context — at the moment each choice becomes real, not all at once on a form. Every consent is optional and default-OFF; you can use Swomi without granting any of them.

A separate Model Improvement consent (default OFF) governs whether your pseudonymized/aggregated data helps improve Swomi’s own systems. It is distinct from group contribution.

5.2 Groups and Shared Intelligence

Actors can participate in shared intelligences scoped to groups you select; a group becomes more capable than its members alone. What a group accumulates is capability, abstracted from its members — not a collection of member profiles, and no member can read another member’s contribution.

The contribution retraction window. When your Actor contributes its learning to a group, that contribution is held separately and remains retractable for 30 days. Within that window you can withdraw it and it is removed. After 30 days it is blended into the group’s collective intelligence and can no longer be individually withdrawn — at that point it has been irreversibly combined and is no longer identifiable to you. We tell you this clearly before you contribute.

You can always stop future contributions and leave a group; what you cannot do is reverse contributions already blended past the 30-day window.

5.3 Revocation & Erasure

You can revoke consent at any time in Settings > Privacy Controls.

6. Special Category Data (Psychological Inferences)

7. Crisis & Distress Support

If our system detects that you may be in distress, it will respond with care in the moment and surface real support resources. This detection is transient: it shapes the immediate response only.

8. Data Retention

Data Category Retention Period Justification
Account Information Account duration + 30 days Service delivery; contract.
Chat History Account duration (deletable anytime) Service delivery; contract.
Zone A (Security) 30 days; up to 1 year (confirmed threats) System protection; legitimate interest.
Sovereign Profile (Zone B) 30 days (default) or up to 5 years (opt-in) Consent; storage limitation.
Zone B Embeddings Purged within 30 days of erasure request Consent + erasure right.
Group Contribution (pre-blend) Retractable for 30 days, then blended (irreversible) Consent; anonymization boundary.
Special-Category Store Only with consent; separate, access-restricted Art. 9 explicit consent.
Group Membership Until you leave the group / account duration Consent.
Model Improvement Data Indefinite (aggregated/pseudonymized) Consent (irreversible once incorporated).
Consent Records Account duration + 7 years Accountability; legal obligation.
Audit Logs 7 years (hash-chained) GDPR Art. 5(2); Law 25.

Audit logs are hash-chained and immutable. If you request erasure, your identity is removed from the chain while cryptographic integrity is preserved.

9. Security Profiling Details

We conduct a Legitimate Interest Balancing Test for security profiling (Zone A).

10. International Data Transfers

Swomi is a Canadian company and data is primarily processed in Canada.

11. Your Privacy Rights

You can exercise rights via the Data Rights Portal in your dashboard:

11.1 Inviting Others

Swomi may help you invite people you already know and choose — for example, contacts you select. We do not generate or source lists of people for you to invite, we never contact a person you did not choose, and if an invited person does not join, we do not retain their data.

12. European Union & United Kingdom Requirements

13. Quebec Law 25 / Canadian Requirements

14. Children’s Privacy

15. Data Security & Documentation

We implement encryption (TLS 1.3 in transit, AES-256 at rest), role-based access control, MFA for administrative access, and hash-chained audit logs.

Trust Center documents:

16. Changes & Contact

Last Updated: June 4, 2026 | Version: 1.3 (Draft for Legal Review)

Part of the Swomi Trust Center. Version 1.3 (Draft for Legal Review) · Effective June 4, 2026. Swomi does not scrape, source, or cold-contact non-users, does not sell personal data, and does not use it for targeted advertising.

swomi.com · Trust Center · Terms of Service · Sign in